CVE-2024-55017
Severity CVSS v4.0:
Pending analysis
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
30/09/2025
Last modified:
02/10/2025
Description
Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allows attackers to intercept authorization codes and gain unauthorized access to victim accounts.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



